CVE-2023-20198

● KEV CRITICAL

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Softw...

Affects 5 products across 2 vendors.

BCS10.0
CVSS 3.110.0
EPSS99.6%
Percentile100th
PatchUnknown
KEV Added2023-10-16
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-420: CWE-420
◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in the web UI feature of Cisco IOS XE Software allows an unauthenticated attacker to gain initial access and create a local user account. The attacker can then escalate privileges to root and deploy an implant. This poses a significant risk to network infrastructure and could disrupt critical operations, especially in industrial settings where network devices manage communication between control systems and HMIs.

BSID: BS-2023-GLOBAL-257171-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-20198?
A critical vulnerability in the web UI feature of Cisco IOS XE Software allows an unauthenticated attacker to gain initial access and create a local user account. The attacker can then escalate privileges to root and deploy an implant. This poses a significant risk to network infrastructure and could disrupt critical operations, especially in industrial settings where network devices manage communication between control systems and HMIs.
What is the CVSS score for CVE-2023-20198?
CVE-2023-20198 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 99.6%.
Is CVE-2023-20198 actively exploited?
Yes. CVE-2023-20198 is in the CISA KEV catalog (added 2023-10-16). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2023-20198?
Priority: IMMEDIATE. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-webui-privesc-j22SaA4z PSIRT: [email protected]
What systems are affected by CVE-2023-20198?
CVE-2023-20198 affects: Cisco, Rockwell Automation, Rockwell Automation, Rockwell Automation, Rockwell Automation.
What NERC-CIP standard applies to CVE-2023-20198?
NERC CIP CIP-007 CIP-007-R1: CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable web management interface represents an unnecessary service on BES Cyber Assets if remote management is not required.
What IEC 62443 requirement maps to CVE-2023-20198?
IEC 62443 SR 3.5: IEC 62443 SR 3.5 (Input Validation) is directly violated. The firmware fails to validate input parameters before processing, enabling unauthorized access and privilege escalation.
Vulnerability Details
CVE IDCVE-2023-20198
BSIDBS-2023-GLOBAL-257171-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2023-10-16
Last Modified2026-06-17
ICS Relevance75%
Weakness (CWE)
Verticals
ICS-OT
Domains
NETWORK-INFRA
SourceNVD
Official Description

Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two previously unknown issues. The attacker first exploited CVE-2023-20198 to gain initial access and issued a privilege 15 command to create a local user and password combination. This allowed the user to log in with normal user access. The attacker then exploited another component of the web UI feature, leveraging the new local user to elevate privilege to root and write the implant to the file system. Cisco has assigned CVE-2023-20273 to this issue. CVE-2023-20198 has been assigned a CVSS Score of 10.0. CVE-2023-20273 has been assigned a CVSS Score of 7.2. Both of these CVEs are being tracked by CSCwh87343.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability exists in the web UI feature of Cisco IOS XE Software. An unauthenticated attacker can exploit CVE-2023-20198 by sending a crafted HTTP request to the web interface, which allows them to gain initial access and create a local user account with normal user privileges. The attacker then leverages this account to exploit another vulnerability (CVE-2023-20273) to escalate privileges to root. With root access, the attacker can modify the file system, deploy implants, and potentially disrupt industrial processes by manipulating network configurations. The attacker must have network access to the web interface, typically reachable from the same network segment as the device.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cisco Ios Xe —
Rockwell Automation Allen-Bradley Stratix 5200 Firmware —
Rockwell Automation Allen-Bradley Stratix 5200 —
Rockwell Automation Allen-Bradley Stratix 5800 Firmware —
Rockwell Automation Allen-Bradley Stratix 5800 —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 1078 Days
CISA KEV● Active Exploitation Confirmed (added 2023-10-16)
Public ExploitNot confirmed
PoC CodeNot confirmed
● Compensating Controls — AI-drafted, review before deploying MEDIUM CONFIDENCE

Implement strict access controls on the web interface of affected Cisco devices. Restrict access to the web interface to trusted IP addresses using ACLs at the network perimeter (Purdue Level 2/3 boundary). Enable HTTPS and disable HTTP management. Consider deploying a web application firewall (WAF) to monitor and block suspicious activity.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. A network rule is only drafted when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R1
CIP-007-R1 requires the identification and disabling of unnecessary ports and services. The vulnerable web management interface represents an unnecessary service on BES Cyber Assets if remote management is not required.
IEC 62443: SR 3.5
IEC 62443 SR 3.5 (Input Validation) is directly violated. The firmware fails to validate input parameters before processing, enabling unauthorized access and privilege escalation.

Drafted by AI and not validated for your network. Test in an isolated environment before any production deployment. Compensating control only - does not replace vendor patch.

AI Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-23
SHA-512 Audit Hash2896e931043d985973440e7ad50303a0d43a3470d7a42d604bd452d6decf3c5e29a960da27a2c478cc1f77d64fcaa072545d0e295e632f2e0fc9cec9b4fae6df
Related CVEs affecting Cisco
CVE-2007-1257 10.0 The Network Analysis Module (NAM) in Cisco Catalyst Series 6000, 6500, and 76... CVE-2009-1167 10.0 Unspecified vulnerability on the Cisco Wireless LAN Controller (WLC) platform... CVE-2011-0364 10.0 The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6... CVE-2011-0382 10.0 The CGI subsystem on Cisco TelePresence Recording Server devices with softwar... CVE-2011-2738 10.0 Multiple unspecified vulnerabilities in Cisco Unified Service Monitor before ...
View all Cisco CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2023-20198 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →